Malicious
Classifications
Spyware Stealer
Threat Names
KematianStealer
Dynamic Analysis Report
Created on 2024-06-28T11:19:01+00:00
qrjeodq.bat
Windows Batch File
Remarks (2/2)
(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "1 day, 13 hours, 41 minutes, 9 seconds" to "1 minute, 20 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
18382f6c7f8b52c779243c6cc7d4cbc51a95d31d40bc748bc2ec65c63219c358 | Downloaded File | Text |
Malicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KematianStealer | KematianStealer | Stealer |
5/5
|
...
|
PowerShell_Execution_Commands | PowerShell command execution detected | - |
4/5
|
...
|
C:\Users\5AlR3U30D3\AppData\Local\Temp\0090F567-A6D3-0000-0000-000000000000_DE_MYB7ZA2AF_2024-06-28_UTC1.zip | Dropped File | ZIP |
Clean
|
...
|
»
Archive Information
»
Number of Files | 2 |
Number of Folders | 1 |
Size of Packed Archive Contents | 3.48 KB |
Size of Unpacked Archive Contents | 15.49 KB |
File Format | zip |
Contents (2)
»
File Name | Packed Size | Unpacked Size | Compression | Is Encrypted | Modify Time | Verdict | Recursively Submitted | Actions |
---|---|---|---|---|---|---|---|---|
DE-(MYB7ZA2AF)-(2024-06-28)-(UTC1)\productkey.txt | 42 Bytes | 46 Bytes | Deflate | False | 2024-06-28 13:22 (UTC) |
Clean
|
- |
...
|
DE-(MYB7ZA2AF)-(2024-06-28)-(UTC1)\System.txt | 3.44 KB | 15.44 KB | Deflate | False | 2024-06-28 13:22 (UTC) |
Clean
|
- |
...
|
C:\Users\5AlR3U30D3\AppData\Roaming\Kematian\DE-(MYB7ZA2AF)-(2024-06-28)-(UTC1)\System.txt | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\utblrtvk\utblrtvk.0.cs | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\4gj5bbza\4gj5bbza.0.cs | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\utblrtvk\utblrtvk.out | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\utblrtvk\utblrtvk.cmdline | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\x0apuumx\x0apuumx.0.cs | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\4gj5bbza\4gj5bbza.out | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\x0apuumx\x0apuumx.out | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\hyrv1kt1\hyrv1kt1.out | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\x0apuumx\x0apuumx.cmdline | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\hyrv1kt1\hyrv1kt1.cmdline | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\4gj5bbza\4gj5bbza.cmdline | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\hyrv1kt1\hyrv1kt1.0.cs | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Roaming\Kematian\DE-(MYB7ZA2AF)-(2024-06-28)-(UTC1)\productkey.txt | Dropped File | Text |
Clean
|
...
|
»
C:\Users\5AlR3U30D3\AppData\Local\Temp\4gj5bbza\4gj5bbza.dll | Dropped File | Empty |
Clean
|
...
|
»
b94954783a3a0c42d37cd001fce737c66790f69d3566ab7aa3fcbca8e1bb5536 | Downloaded File | Text |
Clean
|
...
|
»
bd0840287010fac9d8b291636721cae400e5403980f65c57a23d3d1470472e7e | Downloaded File | Text |
Clean
|
...
|
»
fd95c6be1e1e2d1788f6484bf2e0e9b35a949922273818482815c585afcf4826 | Downloaded File | Unknown |
Clean
|
...
|
»
73b2715ef864a02d104ccb28016b3dcbcaa950607d4abf25cbfbd58e873d671c | Downloaded File | Text |
Clean
|
...
|
»
98e732545c4fa316895d0bcab7aad08d5a48ac42eaf76c7e9fee1de0ff7a66bb | Downloaded File | Text |
Clean
|
...
|
»
2ed27c1421e6928dbe13dbfdb5c59e1045b30341fe7ebe05700006bc5ac572c0 | Downloaded File | Text |
Clean
|
...
|
»